CVE-2007-0646

iMovie HD 6.0.3 and Safari in Mac OS X 10.4-10.4.10 - Denial of Service via Format String in Filename

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-0646. PoCs published by LMH.

AI-analyzed exploit summary This exploit leverages a format-string vulnerability in multiple Mac OS X applications (Help Viewer, Safari, iPhoto, iMovie) by creating a maliciously named file. The '%n' format specifiers in the filename can write arbitrary data to memory, potentially leading to remote code execution.

Description

Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSRunCriticalAlertPanel Apple AppKit function.

Exploits (1)

exploitdb WORKING POC VERIFIED
by LMH · textdososx
https://www.exploit-db.com/exploits/29551

This exploit leverages a format-string vulnerability in multiple Mac OS X applications (Help Viewer, Safari, iPhoto, iMovie) by creating a maliciously named file. The '%n' format specifiers in the filename can write arbitrary data to memory, potentially leading to remote code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Racy
Target: Help Viewer 3.0.0, Safari 2.0.4, iMovie HD 6.0.3, iPhoto 6.0.5
No auth needed
Prerequisites: Ability to create a file with a crafted name on the target system · Victim interaction to open the file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (13)

Core 13
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/24966
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26444
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/22326
Vendor Advisory x_refsource_confirm
http://docs.info.apple.com/article.html?artnum=305391
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA07-109A.html
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html
Vendor Advisory x_refsource_confirm
http://docs.info.apple.com/article.html?artnum=307041
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/3868
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27643
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1470
Exploit, Vendor Advisory x_refsource_misc
http://www.digitalmunition.com/MOAB-30-01-2007.html
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA07-319A.html

Scores

EPSS 0.0987
EPSS Percentile 95.0%

Details

CWE
CWE-134
Status published
Products (3)
apple/imovie 6.0.3
apple/mac_os_x 10.3.9
apple/safari
Published Feb 01, 2007
Tracked Since Feb 18, 2026